LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-12894

Published
CVSS8.8
Severityhigh
WeaknessCWE-1336
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12894

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12894.